CVE-2026-24054General(katacontainers / kata_containers)

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an empty snapshotter directory for the container rootfs. When the Kata runtime attempts to mount the container rootfs, the bind mount causes the rootfs to be detected as a block device, leading to the underlying device being hotplugged to the guest. This can cause filesystem-level errors on the host due to double inode allocation, and may lead to the host's block device being mounted as read-only. Version 3.26.0 contains a patch for the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kata_containers

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
kata_containers

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-29: 2Technical Details · 2026-01-29: 101-29
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24054 Kata Containers Rootfs Mounting Vulnerability Leading to Host Filesystem Errors https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24054

    Post summary

    The excerpt merely announces CVE‑2026‑24054 as a rootfs mounting issue in Kata Containers, with no additional technical detail, exploitation evidence, or remediation information.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24054 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior … https://www.cve.org/CVERecord?id=CVE-2026-24054

    Post summary

    The text merely notes the existence of CVE‑2026‑24054 for Kata Containers and provides a link to the CVE record, offering no further technical or exploitation details.

    00000179
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkatacontainerskata_containers---

Explore more